Unfortunately all "secure" or "trusted" computing efforts seems to be focused on depriving the owner of permissions and command over the computer, and instead transfer that to large copyright holders.
But I suppose the Android security model would make sense, which seems to be based on a traditional unix security model combined with that each program will run as a separate user and having it's own set of group memberships.
As long as I don't need to install a rootkit on my own computer.
Consider a user that has no idea what SSL, TLS, Certificates, Encryption, HTTP, drivers, program signing even mean. What do you put in the prompt that would allow the user to make an informed decision about whether a program they downloaded should be able to install a cert?
If Microsoft (or any vendor) wants to sell security, they have to be responsible. Then they have to sign the drivers.
Yes, it's a whole lot of Single Point of Fuck, but that's what it takes. Hence we have the CA model. We have a "few" trusted authorities.
This could be made into a reputation market thing. So the user could buy security from a vendor. If a vendor is too strict, it'll have few users. If a vendor is too lax, we need a negative signal to penalize its reputation, maybe IP packets should contain a sort of fingerprint of the vendor. So if we see a lot of spam/DDoS from a vendor, it should cost them.
User testing revealed that most users clicked the little cross in the top corner.
:headwall:
Except when it isn't: https://www.extremetech.com/extreme/229040-microsofts-latest...
The original discussion was on the level of "assuming we can trust the OS that it's not trying to trick us, this dialog helps us decide whether to trust the app." As we have seen in the past, Windows no longer upholds this assumption.
On smartphones permissions are pretty obvious (Camera, Contacts, Location, Pictures) but even they sometimes have consequences beyond the obvious.
How would would one even begin to word a certificate store permission so that the average person would understand the consequences of it?
> " Mom, just click OK whenever this box pops up"
> Do you trust this program to make security changes to your device? [More details]
Developers get away with this because, 1) individually selecting permissions is growing rare and 2) there's no pressure to explain why a permission is needed, nor specific contracts to agree upon on how the general permission may be utilized.
- Using sys.whatever.whatever [redtext][Should only ever be used for debugging.]
I can't remember what app it was but it had an insane amount of unnecessary permissions even though it was just a simple app. I used to tell people it was my NSA app.
The counter to that is that now I believe there are a bunch of Exchange clients on Android that will simply ignore server policy or where handling of policy can be controlled in the settings, which kind of defeats the point.
The original point of all those policies was to be able to erase supposedly secure content if the device was lost or if someone left the company for whatever reason.
Edit: the Exchange client I was thinking of is TouchDown, now owned (and EOLed) by Symantec but I believe originally from NitroDesk.
Same way you educate people on how to vote: functional literacy [0]. If people are functionally illiterate, they are going to struggle in all sorts of ways. One of the big drawbacks of our society is that its complexity seems to be growing without bound. This places ever-higher demands on people's ability to read, interpret, and act upon important information in their daily lives.
But device drivers for a desktop machine? The user has paid good money for that device and are going to grant every permission they need to get it working. Asking for each permission individually is just noise.
But the problem is the user interface and programming environment is shit for anything past basic stabby finger novelty apps and no one trusts them enough to invest heavily in it. Oh and the store is a desert of turdblossoms.
https://developer.microsoft.com/en-us/windows/bridges/deskto...
UWP is more than capable of supporting advanced, quality desktop apps. The issue is just that while Windows 7 is so prevalent, developers have little reason to prioritize native UWP dev, which won't run on half the Windows userbase.
I trust my distro vendor, but on Windows this likely remain the wild west for years to come.